Improper input validation in Apache Struts - CVE-2017-15707
Published: December 1, 2017 / Updated: December 2, 2017
Apache Struts
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the REST Plugin is using an outdated JSON-lib library, which is vulnerable to DoS attack. A remote attacker can send a request with specially crafted JSON payload and perform a denial of service (DoS) attack.